In the Linux kernel, the following vulnerability has been resolved:
ext4: fix BUG_ON() when directory entry has invalid rec_len
The rec_len field in the directory entry has to be a multiple of 4. A corrupted filesystem image can be used to hit a BUG() in ext4_rec_len_to_disk(), called from make_indexed_dir().
------------[ cut here ]------------ kernel BUG at fs/ext4/ext4.h:2413! ... RIP: 0010:make_indexed_dir+0x53f/0x5f0 ... Call Trace: <TASK> ? add_dirent_to_buf+0x1b2/0x200 ext4_add_entry+0x36e/0x480 ext4_add_nondir+0x2b/0xc0 ext4_create+0x163/0x200 path_openat+0x635/0xe90 do_filp_open+0xb4/0x160 ? __create_object.isra.0+0x1de/0x3b0 ? _raw_spin_unlock+0x12/0x30 do_sys_openat2+0x91/0x150 __x64_sys_open+0x6c/0xa0 do_syscall_64+0x3c/0x80 entry_SYSCALL_64_after_hwframe+0x46/0xb0
The fix simply adds a call to ext4_check_dir_entry() to validate the directory entry, returning -EFSCORRUPTED if the entry is invalid.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-headersUpgrade kernel-livepatch-5.15.79-51.138Upgrade kernelUpgrade python-perf-debuginfoUpgrade kernel-debuginfo-common-aarch64Upgrade perfUpgrade kernel-toolsUpgrade kernel-livepatch-5.10.155-138.670Upgrade perf-debuginfoUpgrade kernel-tools-develUpgrade kernel-debuginfo-common-x86_64Upgrade bpftool-debuginfoUpgrade kernel-debuginfoUpgrade bpftoolUpgrade kernel-develUpgrade python-perfUpgrade kernel-tools-debuginfo | Jun 23, 2025 | May 1, 2025 |
| Debian | — | Upgrade linux | May 5, 2025 | May 1, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade python3-perfUpgrade bpftoolUpgrade kernel-toolsUpgrade kernelUpgrade kernel-tools-libsUpgrade kernel-abi-stablelists | Aug 13, 2025 | Aug 9, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 1, 2025 |
| Ubuntu | — | Upgrade linux-oracle-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-gcp-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-iotUpgrade linux-aws-5.4Upgrade linux-gkeUpgrade linux-realtimeUpgrade linux-raspiUpgrade linux-raspi-5.4Upgrade linux-kvmUpgrade linux-hwe-5.15Upgrade linux-awsUpgrade linux-aws-5.15Upgrade linux-bluefieldUpgrade linux-azure-fdeUpgrade linux-oracle-5.4Upgrade linux-lowlatencyUpgrade linux-azureUpgrade linux-aws-fipsUpgrade linux-gcpUpgrade linux-ibmUpgrade linux-hwe-5.4Upgrade linux-gcp-5.4Upgrade linux-azure-5.4Upgrade linux-azure-fde-5.15Upgrade linux-gkeopUpgrade linuxUpgrade linux-azure-5.15Upgrade linux-gcp-fipsUpgrade linux-riscv-5.15Upgrade linux-ibm-5.4Upgrade linux-azure-fipsUpgrade linux-intel-iotgUpgrade linux-fipsUpgrade linux-nvidiaUpgrade linux-xilinx-zynqmpUpgrade linux-oracle | May 6, 2025 | May 1, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | May 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub